Splunk Enterprise

Is it OK to manually delete unused warm buckets on my IDX?

ezmo1982
Path Finder

Hi,

My Splunk environment is on-prem. I have a single IDX which runs RHEL on a physical stand-alone server. Indexes are stored on a RAID 5 disk configuration on the same server.

My disk is starting to fill up and I was wondering if is is possible to manually delete older warm bucket files on my IDX (basically running an rm linux command)? The indexes in question are not being used/written to any more, so I dont need to search/access them again.

Is this OK to do? Will it create any inconsistency issues or errors in my Splunk env?

Thanks. 

Labels (1)
0 Karma

ezmo1982
Path Finder

i have retention policies set up on my indexes. It is based on age. It is set for all index types and i dont want to set up retention policies for individual ones. But i just want to know if manually deleting warm buckets cause any issues?

0 Karma

somesoni2
Revered Legend

Why not setup appropriate retention policies on your indexes (since you do not use/search old data), so that Splunk will automatically take care of the cleaning up space. You can setup retention based on age of data OR total size of index.

https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Setaretirementandarchivingpolicy

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...